NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3164 most downloaded on npm
Low-Level OAuth 2 / OpenID Connect Client API for JavaScript Runtimes
Last release 28 days ago
05 Sep 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
7 versions withdrawn
withdrawn after publishing
4 years old
79 releases · first in 2022
One column per quarter.
allow Record and string[][] as parameter arguments
brand URLSearchParams instead of extending URLSearchParams
This release was merely to test release automation. NPM releases now include provenance statements.
This release was merely to test release automation. NPM releases now include provenance statements.
### Refactor * types: enforce flat interfaces
return undefined from getValidatedIdTokenClaims as documented
allow the client's assumed current time to be adjusted (5051a5d), closes #49 #50
// client's local clock is mistakenly 1 hour in the past
const client: oauth.Client = {
client_id: 'abc4ba37-4ab8-49b5-99d4-9441ba35d428',
// ... other metadata
[oauth.clockSkew]: +(60 * 60),
}
// client's local clock is mistakenly 1 hour in the future
const client: oauth.Client = {
client_id: 'abc4ba37-4ab8-49b5-99d4-9441ba35d428',
// ... other metadata
[oauth.clockSkew]: -(60 * 60),
}
// Tolerate 30 seconds clock skew when validating JWT claims like `exp` or `nbf`.
const client: oauth.Client = {
client_id: 'abc4ba37-4ab8-49b5-99d4-9441ba35d428',
// ... other metadata
[oauth.clockTolerance]: 30,
}
add more asymmetric JWS algorithms
build: fixup user agent version after version bump
This release contains only code refactoring and documentation updates.
This release contains only code refactoring and documentation updates.
### Refactor * weak maps instead of symbols
omit zealous response cloning() to reduce edge compute memory bills (a785223), closes #37
Nothing published for this version
claims parameter encoding in issued request objects
Use the TLS server validation in processAuthorizationCodeOpenIDResponse to validate the issuer instead of checking the ID Token's signature. The funct
processAuthorizationCodeOpenIDResponse to validate the issuer instead of checking the ID Token's signature. The function's options argument was removed.processDeviceCodeResponse to validate the issuer instead of checking the optional ID Token's signature. The function's options argument was removed.processIntrospectionResponse to validate the issuer instead of checking the optional JWT Introspection Response signature. The function's options argument was removed.processRefreshTokenResponse to validate the issuer instead of checking the optional ID Token's signature. The function's options argument was removed.processUserInfoResponse to validate the issuer instead of checking the optional JWT UserInfo Response signature. The function's options argument was removed.dpop_jkt to the authorization request.calculateJwkThumbprint function export.jwksRequest function export.processJwksResponse function export.deno: add mod.ts to deno.land/x
### Features * add bun as a supported runtime
allow to skip JWT signature validation on select responses
add a type check on AbortSignal
moves the package on npm from @panva/oauth4webapi to just oauth4webapi
This release
@panva/oauth4webapi to just oauth4webapidoauth to oauth4webapiOtherwise this release contains only code refactoring and documentation updates.
NB: @panva/oauth4webapi had last npm version released and it now simply re-exports oauth4webapi to allow existing consumers to obtain updates within the ^1.2.1 semver range.
Your coding agent can read these notes before it upgrades. Set up the MCP server →